๐Ÿ” CVE Alert

CVE-2026-16262

UNKNOWN 0.0

Estatik < 4.3.3 - Login CSRF

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.

Vendor unknown
Product estatik real estate plugin
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown estatik real estate plugin

Be the first to know when new unknown vulnerabilities affecting unknown estatik real estate plugin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Estatik Real Estate Plugin
0 < 4.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5930f82f-8dc8-41b1-8b78-c71883e7ef22/

Credits

Yaswanth Reddy Sunkara WPScan